cloud-base-extension-coin[.]pages[.]dev
“Coinbase Chrome Extension – Secure Wallet Access”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
PhishDestroy identifies the domain cloud-base-extension-coin.pages.dev as a generic phishing host active since seed 01ce28. This page is being tracked for potential crypto drainer activity, likely targeting cryptocurrency users by impersonating legitimate cloud-based extensions or services. No specific drainer kit fingerprint has been publicly documented, but the page structure and deployment via Pages.dev suggest a lightweight, Cloudflare-hosted lure designed to deceive visitors into connecting wallets or entering seed phrases. The site’s branding remains ambiguous, though the inclusion of 'coin' in the subdomain hints at a crypto-related lure. This domain resolves to IP address 188.114.97.3, a Cloudflare edge node commonly used to obfuscate origin infrastructure. It was registered through Cloudflare, Inc., leveraging the platform’s Pages service for rapid deployment and evasion. The domain holds a valid SSL certificate issued by Google Trust Services, which may help bypass browser security warnings. As of latest inspection, VirusTotal reports 6 out of 95 detection engines flagged the URL, indicating it remains under the radar. The domain has not been listed on Google Safe Browsing (GSB) at this time. Historical analysis shows no prior blocklist presence, suggesting a recently activated campaign. Current status is active and under investigation by threat intelligence teams. Users are advised to avoid interaction and consider blocking the domain at the network level. While current risk is elevated due to active availability and lack of AV detection, the absence from GSB and blocklists limits immediate protective coverage. Organizations should monitor for wallet connection prompts and seed phrase entry requests from similar domains. Remaining risk is moderate; however, rapid deployment via Pages.dev and Cloudflare suggests this campaign may scale quickly. Immediate mitigation includes DNS blocking, browser-level restrictions, and reporting to threat intelligence feeds to raise detection coverage.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of cloud-base-extension-coin.pages.dev · checked Mar 30, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo